peter bassill · operator
$ cve CVE-2008-4456 JSON

CVE-2008-4456 EXPLOIT

2.6
LOW · CVSS 2.0 · EPSS 7% (pctl 94)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.

Scoring

CVSS2.6 (LOW, v2.0)
VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS7.05% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2008-10-06
Last modified2026-06-16

Affected (2)

VendorProduct
mysqlmysql
oraclemysql

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD